A new critical vulnerability affects Elementor Pro and may allow arbitrary files to be uploaded to a WordPress website. Here’s what it means, which websites may be affected, and what you should do to stay protected.
Anyone who manages a WordPress website knows how important it is to keep plugins and themes up to date. At the moment, particular attention should be paid to Elementor Pro, one of the most widely used tools for building WordPress websites.
A critical vulnerability, identified as CVE-2026-32475, has been discovered in Elementor Pro, with a CVSS score of 9.8 out of 10.
Under certain conditions, the vulnerability could allow an unauthenticated attacker to upload arbitrary files to the server. If the uploaded file can subsequently be executed, the consequences can be serious, potentially allowing the attacker to compromise the entire website.
The vulnerability has been fixed in Elementor Pro version 4.2.2, released on August 19, 2026.
What does the vulnerability affect?
The issue affects Elementor Pro versions 4.2.1 and earlier.
The vulnerability is related to Elementor Pro’s Form widget, specifically forms that include a file upload field.
This makes the issue particularly relevant for websites that use public forms allowing visitors to upload documents, images, or other files.
Having a file upload field does not automatically mean that a website has been compromised. However, it is one of the conditions involved in the vulnerability.
Why can uploading a file be dangerous?
A “File Upload” field may seem like a completely normal feature.
For example, a website may allow users to:
- attach a document to an information request;
- submit a CV or resume;
- upload an image;
- provide documentation;
- send a file through a contact form.
The server must, however, carefully verify what type of file is being uploaded.
A properly secured system should prevent users from uploading executable files when they are not required.
The vulnerability discovered in Elementor Pro can allow some of these security checks to be bypassed under certain conditions.
This means that an attacker may be able to upload a file that should normally be rejected.
If that file can subsequently be executed by the web server, the issue can become a Remote Code Execution (RCE) vulnerability.
This is the main reason why the issue has been classified as critical.
Authentication is not necessarily required
One of the most important aspects of this vulnerability is that an attacker does not necessarily need to be logged in to the website.
In other words, exploiting the vulnerability does not necessarily require access to an administrator account or stolen WordPress credentials.
An attacker can attempt to exploit the issue through a publicly accessible Elementor Pro form when the required conditions are present.
This makes it particularly important to address vulnerable installations as soon as possible.
Which versions are affected?
The situation is straightforward:
| Elementor Pro version | Status |
|---|---|
| 4.2.1 and earlier | 🔴 Vulnerable |
| 4.2.2 and later | 🟢 Fixed |
The fixed version was released on August 19, 2026.
If your website is running Elementor Pro 4.2.1 or earlier, updating should be considered a priority.
What should you do?
The first step is to check which version of Elementor Pro is installed on your website.
From the WordPress administration panel, you can normally find the installed version under:
Plugins → Installed Plugins → Elementor Pro
If the installed version is earlier than 4.2.2, we recommend updating it.
Before performing the update, especially on business websites, e-commerce stores, or websites with extensive customizations, it is always good practice to have a recent backup of both the website and database.
What if the website stops working properly after the update?
Security updates are essential, but on complex WordPress websites, updates can sometimes cause compatibility issues with other plugins, themes, or custom code.
For this reason, after an important update it is a good idea to check at least:
- the homepage and main pages;
- contact forms;
- forms with file uploads;
- menus and navigation;
- e-commerce functionality;
- restricted or private areas;
- integrations with external services.
If your website starts showing errors, pages are no longer displayed correctly, forms stop working, or you notice other unusual behavior, avoid making random changes or disabling plugins without first identifying the cause of the problem.
What if you don’t know which version is installed?
That’s not a problem.
If you are not sure which version of Elementor Pro is installed, you don’t know whether your website uses the Form widget affected by the vulnerability, or you simply have concerns about the security of your WordPress website, it is better to have the situation checked before making changes.
A security review can be particularly useful for websites that:
- have been running Elementor Pro for a long time;
- are not regularly updated;
- have many plugins installed;
- use forms with file upload functionality;
- contain customizations;
- are already experiencing errors or unusual behavior.
Quick summary
Vulnerability: CVE-2026-32475
Plugin: Elementor Pro
Severity: Critical
CVSS: 9.8/10
Affected versions: 4.2.1 and earlier
Fixed version: 4.2.2
Type: Arbitrary File Upload
Potential impact: Remote Code Execution and website compromise
Specific condition: Certain configurations involving the Form widget and file upload functionality.
Have questions about your WordPress website?
The vulnerability has been fixed, but simply updating the plugin does not necessarily mean that everything is fine. You should verify the installed version and, most importantly, make sure that your website continues to work correctly after the update.
If you have questions about the Elementor Pro version installed on your website, are unsure whether your site may be affected, or have experienced problems after an update, contact us.
We can check your website, identify potential issues, and help you restore the proper operation of any affected functionality.
It is better to have your website checked today than to discover tomorrow that a problem was already there.

